A buffer overflow in Open vSwitch might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Open vSwitch: Remote execution of arbitrary code Date: January 01, 2017 Bugs: #577568 ID: 201701-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in Open vSwitch might allow remote attackers to execute arbitrary code. Background ========= Open vSwitch is a production quality multilayer virtual switch. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/openvswitch < 2.5.0 > = 2.5.0 Description ========== A buffer overflow was discovered in lib/flow.c in ovs-vswitchd. Impact ===== A remote attacker, using a specially crafted MPLS packet, could execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All Open vSwitch users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/openvswitch-2.5.0" References ========= [ 1 ] CVE-2016-2074 https://www.cve.org/CVERecord?id=CVE-2016-2074 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any securityconcerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.